Record summary

CVE-2021-47795 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 25, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List<= 5.3.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBGeoVision Geowebserver 5.3.3 - Local FIle InclusionExploitDB exploitby Ken PyleNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHGeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site ScriptingCVSS 6.2

GeoVision GeoWebServer 5.3.3 and prior is vulnerable to local file inclusion and cross-site scripting due to improper sanitization of user-supplied input in the WebStrings.srf endpoint. An unauthenticated attacker can read arbitrary files from the server or inject malicious scripts.

Impact

Unauthenticated attackers can read arbitrary files from the server via path traversal, or execute arbitrary JavaScript in the victim's browser via reflected XSS.

Remediation

Contact GeoVision support for a patched firmware version that addresses the input sanitization issues.

WeaknessesCWE-22
Authorsshamo0
Template tagscvecve2021geovisiongeowebserverlfixssvulnvkev
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: title:"Geowebserver"

Source: ProjectDiscovery

References

4